The catalogueFederal (Canada)
Federal (Canada)

Federal (Canada) privacy & access decisions

Browse privacy decisions from Federal (Canada) — each with an AI-generated plain-language summary for every ruling.

6 decisions matching
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 27, 2022PIPEDA Findings #2022-006Indexed Jun 30, 2026

PIPEDA Findings #2022-006: Investigation into Trimac’s use of an audio and video surveillance device in its truck cabins

Trimac Transportation Services Inc.

A truck driver complained that Trimac Transportation Services Inc. (Trimac) installed a dash camera in his vehicle that continuously recorded audio and video without his consent, particularly concerned with audio recording. The OPC investigated two main issues: the appropriateness of the audio recording functionality and whether employee consent was required. The OPC found that Trimac's continuous audio recording, even when drivers were off-duty, was disproportionately privacy-intrusive, despite legitimate business needs. Trimac also initially failed to be transparent about the disciplinary purposes of the system, meaning it could not rely on the employment relationship exception to consent. Trimac agreed to implement recommendations to limit audio recording to on-duty hours and restrict access to recorded clips, and has since clarified the system's disciplinary uses to employees. The OPC found the audio recording issue well-founded and conditionally resolved, and the consent issue well-founded and resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-006: Investigation into Trimac’s use of an audio and video surveillance device in its truck cabins

Jul 27, 2022PIPEDA Findings #2022-006
Adjudicator: Philippe Dufresne
Plain-Language Summary

A truck driver complained that Trimac Transportation Services Inc. (Trimac) installed a dash camera in his vehicle that continuously recorded audio and video without his consent, particularly concerned with audio recording. The OPC investigated two main issues: the appropriateness of the audio recording functionality and whether employee consent was required. The OPC found that Trimac's continuous audio recording, even when drivers were off-duty, was disproportionately privacy-intrusive, despite legitimate business needs. Trimac also initially failed to be transparent about the disciplinary purposes of the system, meaning it could not rely on the employment relationship exception to consent. Trimac agreed to implement recommendations to limit audio recording to on-duty hours and restrict access to recorded clips, and has since clarified the system's disciplinary uses to employees. The OPC found the audio recording issue well-founded and conditionally resolved, and the consent issue well-founded and resolved.

Key Issues
  • Whether road safety, asset protection, and employee performance management are appropriate purposes for the continuous collection of in-cabin audio via the System, including when drivers are off-duty and not driving, under subsection 5(3) of PIPEDA.
  • Whether the collection of sensitive personal information (in-cabin audio) was justified given the legitimate need, effectiveness, less privacy-invasive means, and proportionality.
  • Whether employee consent was required for the collection of personal information via the System, specifically whether Trimac could rely on the exception to consent under subsection 7.3 of PIPEDA.
  • Whether Trimac was sufficiently transparent about the disciplinary purposes of its dash camera system to rely on the subsection 7.3 exception to consent.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jul 15, 2022PIPEDA Findings #2022-005Indexed Jun 30, 2026

PIPEDA Findings #2022-005: Hotel chain discovers breach of customer database following acquisition of a competitor

Marriott International, Inc.

On November 30, 2018, Marriott International, Inc. announced a data security breach involving unauthorized access to a Starwood Hotels database, which it had acquired in 2016. The breach, spanning over four years, affected up to 12.8 million Canadian records, including passport and payment card details. The OPC launched an investigation into Luxury Hotels Canada, Marriott's Canadian operating company, following eleven complaints. The investigation found Marriott's security safeguards, accountability measures, and information retention practices to be inadequate, contravening PIPEDA Principles 4.7, 4.1.4, and 4.5. Specifically, Marriott failed to detect the breach sooner due to insufficient logging, monitoring, and multi-factor authentication, and retained personal information longer than necessary. While Marriott's notification to affected individuals was deemed adequate, the OPC had outstanding concerns regarding remote access, unencrypted data storage, and retention periods. The findings are well-founded and conditionally resolved, as Marriott committed to implementing the OPC's recommendations, including engaging an external assessor and reviewing its privacy framework.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-005: Hotel chain discovers breach of customer database following acquisition of a competitor

Jul 15, 2022PIPEDA Findings #2022-005
Adjudicator: Philippe Dufresne
Plain-Language Summary

On November 30, 2018, Marriott International, Inc. announced a data security breach involving unauthorized access to a Starwood Hotels database, which it had acquired in 2016. The breach, spanning over four years, affected up to 12.8 million Canadian records, including passport and payment card details. The OPC launched an investigation into Luxury Hotels Canada, Marriott's Canadian operating company, following eleven complaints. The investigation found Marriott's security safeguards, accountability measures, and information retention practices to be inadequate, contravening PIPEDA Principles 4.7, 4.1.4, and 4.5. Specifically, Marriott failed to detect the breach sooner due to insufficient logging, monitoring, and multi-factor authentication, and retained personal information longer than necessary. While Marriott's notification to affected individuals was deemed adequate, the OPC had outstanding concerns regarding remote access, unencrypted data storage, and retention periods. The findings are well-founded and conditionally resolved, as Marriott committed to implementing the OPC's recommendations, including engaging an external assessor and reviewing its privacy framework.

Key Issues
  • Whether personal information held by Marriott was protected by security safeguards appropriate to the sensitivity of the information as required by Principle 4.7 (Safeguards).
  • Whether Marriott demonstrated due diligence and took steps to fulfil its responsibilities to implement policies and practices to protect personal information under Principle 4.1.4 (Accountability) when acquiring control of the Starwood network.
  • Whether Marriott retained personal information for longer than necessary, relevant to Principle 4.5 (Limiting use, disclosure and retention).
  • Whether the mitigation measures offered by Marriott to affected individuals were adequate to protect their personal information from unauthorized use, such as future identity theft, in accordance with Principle 4.7 (Safeguards).
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Jun 1, 2022PIPEDA Findings #2022-001Indexed Jun 30, 2026

PIPEDA Findings #2022-001: Joint investigation into location tracking by the Tim Hortons App

The TDL Group Corp. (Tim Hortons)

A joint investigation by federal and provincial privacy authorities found that the Tim Hortons App continuously tracked users' granular location data, often every few minutes, even when the app was closed. This data was used to infer home, work, travel status, and visits to competitors. The Offices concluded that Tim Hortons collected this sensitive information for an inappropriate purpose, as it never used the data for its stated goal of targeted advertising, and the privacy loss was disproportionate to any potential benefits. Furthermore, Tim Hortons failed to obtain valid consent, making misleading statements that the app only tracked location when open and not adequately informing users of the extensive nature and consequences of the tracking. Concerns were also raised about inadequate contractual protections with the third-party service provider, Radar, and a broader lack of accountability within Tim Hortons' privacy management. The matter was found well-founded and conditionally resolved, as Tim Hortons agreed to delete the collected data and establish a comprehensive privacy management program.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-001: Joint investigation into location tracking by the Tim Hortons App

Jun 1, 2022PIPEDA Findings #2022-001
Adjudicator: Daniel Therrien
Plain-Language Summary

A joint investigation by federal and provincial privacy authorities found that the Tim Hortons App continuously tracked users' granular location data, often every few minutes, even when the app was closed. This data was used to infer home, work, travel status, and visits to competitors. The Offices concluded that Tim Hortons collected this sensitive information for an inappropriate purpose, as it never used the data for its stated goal of targeted advertising, and the privacy loss was disproportionate to any potential benefits. Furthermore, Tim Hortons failed to obtain valid consent, making misleading statements that the app only tracked location when open and not adequately informing users of the extensive nature and consequences of the tracking. Concerns were also raised about inadequate contractual protections with the third-party service provider, Radar, and a broader lack of accountability within Tim Hortons' privacy management. The matter was found well-founded and conditionally resolved, as Tim Hortons agreed to delete the collected data and establish a comprehensive privacy management program.

Key Issues
  • Whether Tim Hortons collected or used personal information for an appropriate purpose under the Acts.
  • Whether Tim Hortons obtained valid consent for the collection and use of granular location data.
  • Adequacy of contractual protections for personal information transferred to third-party service providers.
  • Tim Hortons' accountability and implementation of a privacy management program.
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
May 19, 2022PIPEDA Findings #2022-004Indexed Jun 30, 2026

PIPEDA Findings #2022-004: Investigation into MGM breach highlights how to assess risk, and need for timely assessment

MGM Resorts International

The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-004: Investigation into MGM breach highlights how to assess risk, and need for timely assessment

May 19, 2022PIPEDA Findings #2022-004
Adjudicator: Daniel Therrien
Plain-Language Summary

The OPC initiated a complaint against MGM Resorts International after media reports revealed a 2019 data breach affecting millions, including Canadians, for which MGM had not reported to the OPC. The investigation focused on whether MGM complied with mandatory breach reporting obligations under PIPEDA. The OPC found that MGM contravened PIPEDA by failing to promptly assess whether the breach posed a real risk of significant harm (RROSH) to affected Canadians and by not reporting the breach or notifying individuals as soon as feasible. MGM had delayed its assessment for Canadians for several months compared to its U.S. customers. In response to OPC recommendations, MGM committed to amending its privacy breach response framework to ensure timely RROSH assessments, reporting to the Commissioner, and notifying affected individuals for future breaches involving Canadians. The matter was found to be well-founded and conditionally resolved.

Key Issues
  • Whether MGM had the obligation to report the breach to the OPC and notify affected Canadians
  • Whether the MGM breach met the RROSH reporting and notification threshold
  • Whether the personal information involved was sensitive
  • Whether there was a high probability of misuse of the personal information
  • Whether MGM notified the OPC and affected Canadians as soon as feasible
Federal (Canada)Personal Information Protection and Electronic Documents ActSettled
Federal (Canada) flag
May 10, 2022PIPEDA Findings #2022-002Indexed Jun 30, 2026

PIPEDA Findings #2022-002: Biron Health Group has ceased sending promotional emails to travellers arriving in Canada who undergo COVID-19 testing

Biron Health Group

The complainant alleged that Biron Health Group (Biron) sent him promotional emails without his consent after he underwent mandatory COVID-19 testing upon arrival at Montreal Trudeau Airport. He provided his email solely for test results. Biron initially believed it had implicit consent due to an established business relationship. The OPC found that Biron could not reasonably assume implicit consent, as travellers had no choice but to use Biron for mandatory testing and would not expect their health information to be used for marketing. Biron ceased the practice and deleted affected email addresses from its marketing database. The complaint was settled during the investigation.

Quick view

Personal Information Protection and Electronic Documents ActSettled

PIPEDA Findings #2022-002: Biron Health Group has ceased sending promotional emails to travellers arriving in Canada who undergo COVID-19 testing

May 10, 2022PIPEDA Findings #2022-002
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Biron Health Group (Biron) sent him promotional emails without his consent after he underwent mandatory COVID-19 testing upon arrival at Montreal Trudeau Airport. He provided his email solely for test results. Biron initially believed it had implicit consent due to an established business relationship. The OPC found that Biron could not reasonably assume implicit consent, as travellers had no choice but to use Biron for mandatory testing and would not expect their health information to be used for marketing. Biron ceased the practice and deleted affected email addresses from its marketing database. The complaint was settled during the investigation.

Key Issues
  • Whether Biron Health Group had implicit consent to send promotional emails to individuals undergoing mandatory COVID-19 testing
  • Whether the collection of personal information for mandatory health testing could be used for secondary marketing purposes
Federal (Canada)Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved
Federal (Canada) flag
Mar 30, 2022PIPEDA Findings #2022-003Indexed Jun 30, 2026

PIPEDA Findings #2022-003: Telecommunications firm failed to obtain appropriate consent for voiceprint authentication program

Rogers Communications Inc.

The complainant alleged that Rogers Communications Inc. improperly enrolled her in its Voice ID voiceprint authentication program without her consent and failed to allow her to opt out or delete her voiceprint. Rogers utilized a passive voiceprinting technology, "tuning," to create algorithmic voiceprints for customer authentication and fraud prevention. The Office of the Privacy Commissioner (OPC) found Rogers' purpose for collecting voiceprints to be appropriate, concluding this aspect of the complaint was not well-founded. However, the OPC determined that Rogers failed to obtain valid and meaningful express consent for the collection of sensitive biometric voiceprints, both during the "tuning" process and enrolment, as customers would not reasonably expect this. Furthermore, Rogers did not provide a clearly explained and easily accessible option for individuals to opt out and improperly retained voiceprints of opted-out individuals without any actual purpose. The OPC also identified deficiencies in Rogers' training materials and monitoring protocols for ensuring staff obtained valid consent. In response to OPC recommendations, Rogers committed to significant changes, including obtaining express consent before tuning, clearly informing customers of opt-out/deletion, deleting retained voiceprints, and improving training and monitoring. Consequently, the consent and retention aspects of the complaint were found to be well-founded and conditionally resolved.

Quick view

Personal Information Protection and Electronic Documents ActWell-founded & conditionally resolved

PIPEDA Findings #2022-003: Telecommunications firm failed to obtain appropriate consent for voiceprint authentication program

Mar 30, 2022PIPEDA Findings #2022-003
Adjudicator: Daniel Therrien
Plain-Language Summary

The complainant alleged that Rogers Communications Inc. improperly enrolled her in its Voice ID voiceprint authentication program without her consent and failed to allow her to opt out or delete her voiceprint. Rogers utilized a passive voiceprinting technology, "tuning," to create algorithmic voiceprints for customer authentication and fraud prevention. The Office of the Privacy Commissioner (OPC) found Rogers' purpose for collecting voiceprints to be appropriate, concluding this aspect of the complaint was not well-founded. However, the OPC determined that Rogers failed to obtain valid and meaningful express consent for the collection of sensitive biometric voiceprints, both during the "tuning" process and enrolment, as customers would not reasonably expect this. Furthermore, Rogers did not provide a clearly explained and easily accessible option for individuals to opt out and improperly retained voiceprints of opted-out individuals without any actual purpose. The OPC also identified deficiencies in Rogers' training materials and monitoring protocols for ensuring staff obtained valid consent. In response to OPC recommendations, Rogers committed to significant changes, including obtaining express consent before tuning, clearly informing customers of opt-out/deletion, deleting retained voiceprints, and improving training and monitoring. Consequently, the consent and retention aspects of the complaint were found to be well-founded and conditionally resolved.

Key Issues
  • Whether the collection and use of voiceprints for authentication and fraud prevention constituted an appropriate purpose under PIPEDA s. 5(3)
  • Whether Rogers obtained valid and meaningful consent for the collection of voiceprints (tuning and enrolment) under PIPEDA Principle 4.3 and s. 6.1
  • Whether Rogers provided an adequate mechanism for the withdrawal of consent under PIPEDA Principle 4.3.8
  • Whether Rogers' retention of voiceprints after opt-out was compliant with PIPEDA Principle 4.5.3
  • Whether Rogers' training materials and protocols for obtaining consent were adequate